The severities shown are the ones that survived review, not the first automated rating. Each finding was read again against the audited code or pages; findings that held up keep or lower their rating, usually because the behaviour is documented, needs unusual configuration, fails loudly, or affects only examples or CI. Findings shown wrong on review, or repeating another finding, are listed separately as excluded. Where a finding was not individually re-checked, its page says so and shows the first rating.
Verdict rule: Fail if a High finding remains after review, otherwise Pass with notes.
How each audit ran: the first eight as an API run on the Nacodex server; the next eight in a cloud session; the October 2026 workstation audits as a local run on our workstation; the earlier documentation audits are our May to September 2026 reports, published as delivered, with their findings re-checked against the live pages on 11 October 2026. All are full audits at Standard review depth.
All audits
| Group | Audited | Date | How it ran | High | Medium | Low | Info | Excluded | Verdict |
|---|---|---|---|---|---|---|---|---|---|
| Open-source projects, first eight · API run on the Nacodex server | |||||||||
| A | auth0/node-jsonwebtoken | 11 October 2026 | API run on the Nacodex server | 0 | 0 | 3 | 3 | 0 | Pass with notes |
| A | JakeWharton/timber | 11 October 2026 | API run on the Nacodex server | 0 | 1 | 8 | 9 | 0 | Pass with notes |
| A | helmetjs/helmet | 11 October 2026 | API run on the Nacodex server | 0 | 0 | 1 | 2 | 0 | Pass with notes |
| A | expressjs/session | 11 October 2026 | API run on the Nacodex server | 0 | 1 | 7 | 2 | 0 | Pass with notes |
| A | paulmillr/noble-ed25519 | 11 October 2026 | API run on the Nacodex server | 0 | 0 | 0 | 6 | 0 | Pass with notes |
| A | android/architecture-samples | 11 October 2026 | API run on the Nacodex server | 0 | 2 | 15 | 12 | 0 | Pass with notes |
| A | anza-xyz/wallet-adapter | 11 October 2026 | API run on the Nacodex server | 0 | 2 | 15 | 4 | 0 | Pass with notes |
| A | solana-foundation/solana-web3.js | 11 October 2026 | API run on the Nacodex server | 0 | 4 | 13 | 6 | 2 | Pass with notes |
| Open-source projects and documentation, eight more · cloud session | |||||||||
| B | Jupiter developer docs: pages changed or added since May | 11 October 2026 | cloud session | 0 | 4 | 56 | 2 | 2 | Pass with notes |
| B | Helius docs: pages changed or added since May | 11 October 2026 | cloud session | 0 | 9 | 81 | 1 | 0 | Pass with notes |
| B | horizontalsystems/unstoppable-wallet-android | 11 October 2026 | cloud session | 0 | 3 | 65 | 1 | 0 | Pass with notes |
| B | solana-foundation/program-examples | 11 October 2026 | cloud session | 2 | 6 | 43 | 3 | 0 | Fail |
| B | sendaifun/solana-agent-kit | 11 October 2026 | cloud session | 3 | 25 | 110 | 0 | 2 | Fail |
| B | android/nowinandroid | 11 October 2026 | cloud session | 0 | 3 | 9 | 15 | 0 | Pass with notes |
| B | Anchor (otter-sec/anchor) | 11 October 2026 | cloud session | 0 | 3 | 35 | 1 | 0 | Pass with notes |
| B | trustwallet/wallet-core | 11 October 2026 | cloud session | 0 | 6 | 46 | 1 | 0 | Pass with notes |
| Workstation audits, October 2026 · local run on our workstation | |||||||||
| C | Solana Mobile developer documentation | 11 October 2026 | local run on our workstation | 0 | 2 | 66 | 8 | 1 | Pass with notes |
| C | Solana Mobile SDKs: mobile-wallet-adapter and seed-vault-sdk | 11 October 2026 | local run on our workstation | 1 | 8 | 137 | 16 | 0 | Fail |
| C | ORE: regolith-labs/ore, entropy and ore-stake | 11 October 2026 | local run on our workstation | 0 | 3 | 46 | 0 | 2 | Pass with notes |
| C | Tensor developer documentation | 11 October 2026 | local run on our workstation | 0 | 1 | 24 | 0 | 1 | Pass with notes |
| C | regolith-labs/steel | 11 October 2026 | local run on our workstation | 0 | 6 | 24 | 0 | 0 | Pass with notes |
| Earlier documentation audits · earlier documentation audit Severities as published in our original report; these findings were not re-reviewed by hand the way the sample audits were. Counts below are as first rated. | |||||||||
| D | Jupiter developer documentation | May 2026 | earlier documentation audit | 7 | 9 | 5 | 0 | 0 | as first rated; not re-reviewed |
| D | Helius API documentation | May 2026 | earlier documentation audit | 2 | 16 | 3 | 0 | 0 | as first rated; not re-reviewed |
| D | Helius Gatekeeper documentation | June 2026 | earlier documentation audit | 2 | 7 | 3 | 0 | 0 | as first rated; not re-reviewed |
| D | Magic Eden developer documentation | May 2026 | earlier documentation audit | 9 | 7 | 5 | 0 | 0 | as first rated; not re-reviewed |
| D | Tensor developer documentation | May 2026 | earlier documentation audit | 7 | 11 | 3 | 0 | 0 | as first rated; not re-reviewed |
| D | Solana Mobile documentation and SDKs | June 2026 | earlier documentation audit | 21 | 25 | 25 | 6 | 2 | as first rated; not re-reviewed |
| D | Solana Mobile stack, third audit | September 2026 | earlier documentation audit | 27 | 60 | 54 | 12 | 0 | as first rated; not re-reviewed |
| Total, reviewed audits | 6 | 89 | 804 | 92 | 10 | ||||
Counts after review for groups A to C. Group D: as first rated in our original reports, not re-reviewed by hand and not included in the totals (Critical counted with High; Advisory with Info); their current status is in the re-check table below.
Documentation re-checks
Earlier this year we audited the developer documentation of five Solana ecosystem services: wrong code samples, dead links, contradictions between pages. On 11 October 2026 we fetched every cited page again and checked each finding against the current text. Each audit page shows the status of every finding.
| Documentation | First audit | Findings | Fixed | Partly fixed | Unchanged | Could not check |
|---|---|---|---|---|---|---|
| Tensor documentation | May 2026 | 21 | 0 | 0 | 20 | 1 |
| Helius API documentation | May 2026 | 21 | 2 | 2 | 15 | 2 |
| Helius Gatekeeper documentation | June 2026 | 12 | 1 | 3 | 8 | 0 |
| Jupiter documentation | May 2026 | 21 | 5 | 2 | 13 | 1 |
| Magic Eden documentation | May 2026 | 21 | 0 | 0 | 0 | 21 |
"Could not check": the page or the finding could not be compared. Magic Eden's documentation site now blocks automated access, so none of its findings could be re-checked. Tensor: 85 of its 90 pages are unchanged since May; the other 5 differ only in formatting.
The page banner and the sitemap used dev.jup.ag. Both now use developers.jup.ag.
The plans page listed seven Ultra endpoints as billable. It no longer does, and the Ultra pages now say they are no longer actively maintained.
All 91 API specifications now point to developers.jup.ag/portal.
It is now on the current host, last updated 7 October 2026.
The 14 May 2026 change is now written as enforced.
They were missing the /docs/ prefix; all eight are now correct, in English and Chinese.
It is now published at helius.dev/openapi/enhanced-api.json and listed in the API catalog.
Both are now served.
In June 2026 we audited the Solana Mobile developer documentation and SDKs and shared the full report with Solana Mobile. In the months that followed, ten of the issues it identified were corrected on the very pages it cited (eight in full, two in part), in the public commits listed below. We did not receive a reply, and the changes do not reference the report. We publish the complete June findings here, together with a fresh audit of the current documentation, so readers can follow what has changed and what remains open.
Public commits to the Solana Mobile documentation that corrected the cited pages:
- 812c43d209886f63c5e1aaa2f1f69140ed4889d1 (21 June 2026)
- dca752d20657acff15f6b3ba434b794c27448a28 (23 June 2026)
- da2f11498e6372909fd905486be9c982516ff7b4 (27 August 2026)
- 142c805b3147efa4c176c300574853214f07a311 (31 August 2026)
- c2699d9423e24dd8465c8e5ee1b3931280cc932f (9 September 2026)
All ten corrections were still in place on 11 October 2026. We do not claim that our report caused them.
The complete June 2026 findings · our September 2026 third audit · the fresh audit of the current documentation (October 2026)
About these samples
- Public code only, each project pinned to the commit named on its page; documentation audits use a dated copy of the published pages
- Full audits at Standard review depth; the route of each audit (API run on the Nacodex server, cloud session, or local run on our workstation) is named on its page
- Findings then re-checked by hand against the code at that commit and, where the lookup could run, compared with the project's public issues
- Documentation re-checks compare the current published text with our earlier report
Project and company names and their code belong to their owners and are used here only to identify what was audited. None of them has endorsed or reviewed these pages. If you maintain one of these projects and think something here is wrong, write to support@nacodex.help: we correct errors promptly and say so on the page.